Article 5A7BA Ubuntu fixes bugs that standard users could use to become root

Ubuntu fixes bugs that standard users could use to become root

by
Dan Goodin
from Ars Technica - All content on (#5A7BA)
hacked-640x438.jpg

(credit: Pixabay)

Ubuntu developers have fixed a series of vulnerabilities that made it easy for standard users to gain coveted root privileges.

This blog post is about an astonishingly straightforward way to escalate privileges on Ubuntu," Kevin Backhouse, a researcher at GitHub, wrote in a post published on Tuesday. With a few simple commands in the terminal, and a few mouse clicks, a standard user can create an administrator account for themselves."

The first series of commands triggered a denial-of-service bug in a daemon called accountsservice, which as its name suggests is used to manage user accounts on the computer. To do this, Backhouse created a Symlink that linked a file named .pam_environment to /dev/zero, changed the regional language setting, and sent accountsservice a SIGSTOP. With the help of a few extra commands, Backhouse was able to set a timer that gave him just enough time to log out of the account before accountsservice crashed.

Read 5 remaining paragraphs | Comments

index?i=rFxq3FqK7Hk:oyWI-gepUcw:V_sGLiPB index?i=rFxq3FqK7Hk:oyWI-gepUcw:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments